Security update for phpMyAdmin

Type: security
Severity: important
Issued: 2019-03-23
This update for phpMyAdmin to version 4.8.5 fixes the following issues:

Security issues fixed:

- CVE-2019-6799: Fixed an arbitrary file read vulnerability (boo#1123272)
- CVE-2019-6798: Fixed a SQL injection in the designer interface (boo#1123271)

Other changes:

* Fix rxport to SQL format not available
* Fix QR code not shown when adding two-factor authentication to a user account
* Fix issue with adding a new user in MySQL 8.0.11 and newer
* Fix frozen interface relating to Text_Plain_Sql plugin
* Fix missing table level operations tab



  • phpMyAdmin-4.8.5-bp150.3.9.1